Reference. Formal Verification of CNN-based Perception Systems
We address the problem of verifying neural-based perception systems implemented by convolutional neural networks. We define a notion of local robustness based on affine and photometric transformations. We show the notion cannot be captured by previously employed notions of robustness. The method proposed is based on reachability analysis for feed-forward neural networks and relies on MILP encodings of both the CNNs and transformations under question. We present an implementation and discuss the experimental results obtained for a CNN trained from the MNIST data set.
Cite
Cited by (1)
Verification of Deep Convolutional Neural Networks Using ImageStars tranVerificationDeepConvolutional2020
Convolutional Neural Networks (CNN) have redefined stateof-the-art in many real-world applications, such as facial recognition, image classification, human pose estimation, and semantic segmentation. Despite their success, CNNs are vulnerable to adversarial attacks, where slight changes to their inputs may lead to sharp changes in their output in even well-trained networks. Set-based analysis methods can detect or prove the absence of bounded adversarial attacks, which can then be used to evaluate the effectiveness of neural network training methodology. Unfortunately, existing verification approaches have limited scalability in terms of the size of networks that can be analyzed.
Cites 20 works (0 here)
External (20)
- AI2: Safety and Robustness Certification of Neural Networks with Abstract Interpretation (2018)
- Verifying Properties of Binarized Deep Neural Networks (2018)
- Reachability Analysis for Neural Agent-Environment Systems (2018)
- A Dual Approach to Scalable Verification of Deep Networks (2018)
- Venus; supplementary material (Anonymous) (2018)
- Formal specification for deep neural networks (Seshia et al., UC Berkeley tech report) (2018)
- Reluplex: An Efficient SMT Solver for Verifying Deep Neural Networks (2017)
- An approach to reachability analysis for feed-forward ReLU neural networks (2017)
- Towards Practical Verification of Machine Learning: The Case of Computer Vision Systems (2017)
- Formal Verification of Piece-Wise Linear Feed-Forward Neural Networks (2017)
- Safety Verification of Deep Neural Networks (2017)
- The Limitations of Deep Learning in Adversarial Settings (2016)
- Deep Learning (Goodfellow, Bengio, Courville) (2016)
- Gurobi optimizer reference manual (2016)
- ImageNet Large Scale Visual Recognition Challenge (2015)
- Image Processing, Analysis, and Machine Vision (2014)
- Explaining and Harnessing Adversarial Examples (2014)
- Pattern Recognition and Machine Learning (Bishop) (2006)
- Multiple View Geometry in Computer Vision (2004)
- Gradient-based learning applied to document recognition (1998)